leftymagazine

Uncompromising journalism for a just planet.

A column by Harrison Lockwood

Encrypted activist apps: how security limits movement growth

Encrypted messaging apps for activist organizing solve a real problem: states, police departments, employers, hostile companies, and political opponents can all exploit unsecured communications.

Harrison Lockwood, Lead Columnist on Systemic Justice & Climate Action·Updated: August 16, 2026·13 min read

Encrypted activist apps: how security limits movement growth

Signal’s end-to-end encryption protects message content in transit. That protection matters. During the 2020 Black Lives Matter protests in the United States, Signal became a widely used tool because organizers understood the basic exposure built into ordinary messaging and social platforms.

But encryption does not create a movement. It does not recruit a neighborhood, fill a meeting, distribute food, coordinate a strike, or persuade someone who has never attended a protest to take a first step. In some circumstances, security controls can make those tasks harder.

That is the central contradiction. The tighter the communications system, the more friction it can impose on recruitment and public mobilization. The more open the system, the more information it exposes to surveillance, harassment, infiltration, and platform manipulation. Activist groups cannot resolve that contradiction with a single app. They need a communications structure that separates public reach from sensitive coordination.

The technology question is therefore a power question. Who needs access? Who faces the greatest risk? Which information would cause material harm if exposed? And how much complexity can a group impose before ordinary people stop participating?

Encryption protects content. It does not protect the whole movement.

End-to-end encryption means that the service provider should not be able to read the contents of messages as they travel between devices. Signal uses the Signal Protocol for that purpose, and its design offers strong protection against routine interception of message content.

That is valuable, but it is narrower than the popular image of an invisible activist channel.

A movement still generates metadata: who communicates with whom, when messages are sent, how large groups become, which devices connect, and how accounts relate to one another. Depending on the service, the available metadata and the legal environment, that information can help authorities map relationships even when they cannot read the messages themselves.

The endpoint also remains vulnerable. If police seize an unlocked phone, encryption in transit cannot undo what the device already displays. If a member uses a weak four-digit PIN, leaves notifications visible on a lock screen, stores sensitive files locally, or gives an app unnecessary permissions, the movement has a security problem that no encryption protocol can solve.

Human error remains the most predictable weakness. A participant can forward a screenshot, add the wrong person to a group, lose a phone, reuse a password, or discuss a sensitive plan in a public channel. A secure tool reduces some risks. It does not remove the people and devices that produce the risks.

This distinction matters because movements often respond to surveillance with a technological reflex: install the most secure application, declare the problem addressed, and move on. That approach transfers responsibility from collective practice to a product. The result looks modern and feels reassuring. It also leaves the underlying exposure intact.

Encryption can protect a conversation. It cannot protect a movement that has confused secrecy with strategy.

Signal’s safety features illustrate the problem. In a usability study involving 28 computer science students, 21 failed to successfully verify a recipient’s public key. These were not people selected for their technical indifference. They had relevant academic training, yet the interface and the underlying security concepts still defeated most of them.

That does not make Signal defective. It shows that security is partly a training and organizational problem. A feature that exists but that users cannot reliably operate does not provide the protection its documentation promises.

The security–reach trade-off is built into organizing

Grassroots groups need at least two different communications functions.

The first is public reach. This includes announcing an event, explaining a campaign, sharing a meeting location, publishing a statement, collecting sign-ups, and reaching people who have no existing relationship with the group. These channels must be accessible. They need to work on ordinary phones, with minimal setup, and without requiring a new participant to understand key verification, disappearing messages, device permissions, or threat modeling before they can attend a rally.

The second is sensitive coordination. This includes decisions about civil disobedience, the identities of vulnerable participants, legal support, emergency contacts, protest logistics, and information that could expose people to retaliation. These conversations require tighter controls and a smaller circle.

The mistake is to force both functions into the same channel.

A closed encrypted group may protect internal discussion, but it also creates a barrier at the exact moment when a movement needs to expand. New participants may need an invitation, a phone number, a specific application, and an explanation of group rules before they can even see what the campaign does. Those requirements may be justified for a core action team. They are counterproductive as the front door.

An open social platform has the opposite problem. It offers discovery and scale while exposing organizers to surveillance, harassment, coordinated reporting, algorithmic suppression, impersonation, and data extraction. The platform benefits from the activity regardless of whether the movement wins. Its business model treats attention and relationships as assets to capture.

This is where corporate and political spin usually enters. Platforms describe their services as neutral infrastructure, while encrypted applications are presented as complete solutions. Neither description survives contact with material reality. A platform’s design reflects its revenue model. An encrypted app’s design reflects its security assumptions. Activists still have to build the operating system of the movement themselves.

What each channel is actually good for

Communication channelStrongest useMain exposureSensible role in a movement
Public social platformsDiscovery, announcements, rapid public mobilizationSurveillance, harassment, platform moderation, relationship mappingPublic-facing outreach, not sensitive planning
Email listsRegular updates, event details, volunteer coordinationAccount compromise, forwarding, list exposureBroad communication with clear consent and data minimization
SMSReaching people who will not install new appsWeak privacy, phone-number exposure, interception risksTime-sensitive mass alerts and basic logistics
Signal groupsSensitive coordination among known participantsMetadata, device seizure, onboarding friction, user errorCore teams, legal support, and high-risk conversations
Offline encryption toolsCommunication during shutdowns or limited connectivityTraining demands, distribution challenges, narrow compatibilitySpecialized use in restrictive environments

The table is not a ranking. It is an argument against technological monogamy. A movement that uses one tool for every task has already accepted the tool’s limitations as its own.

Telegram requires particular care in this discussion. The existence of a privacy-oriented brand does not mean that every conversation on the service receives the same protection. Activists must understand which modes provide end-to-end encryption and which do not, rather than treating the platform name as a security guarantee. The same principle applies elsewhere: the label is not the threat model.

The real bottleneck is often the device in someone’s hand

Security conversations tend to become abstract because abstraction is easier than changing daily behavior. People discuss protocols, servers, and encryption standards while leaving phones unlocked on kitchen tables.

For grassroots organizations, basic device hygiene often produces more practical protection than adding another application. That means replacing weak device PINs with a minimum of six digits, preferably ten; enabling two-factor authentication where available; keeping operating systems updated; reviewing app permissions; limiting sensitive information stored locally; and disabling message previews on lock screens.

None of this is glamorous. It is still where many compromises begin.

A movement should also decide what information it actually needs to retain. Organizers often collect full names, phone numbers, addresses, immigration details, medical information, legal histories, and workplace data because a form makes those fields available. Every unnecessary field creates another liability. Data minimization is not an administrative preference. It reduces the amount of material that can be seized, leaked, subpoenaed, or misused.

The same logic applies to group membership. A large encrypted group is not automatically a secure group. Every participant becomes a possible endpoint, and every endpoint carries its own practices, devices, relationships, and legal exposure. A group chat can be encrypted while still containing people whose phones are shared with family members, whose accounts are compromised, or whose screenshots circulate beyond the intended audience.

That is why high-risk information should not travel through the same structures as routine updates. A public event address does not require the same protection as the identity of someone planning an arrestable action. A volunteer shift does not belong in the same compartment as legal strategy. Treating all information as equally sensitive creates needless barriers. Treating all information as equally harmless creates needless danger.

Security protocols can become a class barrier

The people most likely to be excluded by complicated digital security are not necessarily careless. They may have limited data, older devices, unstable connectivity, language barriers, disabilities, shared phones, or legitimate reasons to avoid installing an unfamiliar application. They may also be new to political organizing and unwilling to accept a long list of technical obligations from a group they do not yet trust.

A movement that treats those barriers as evidence of insufficient commitment will narrow itself socially and politically. It will recruit people who already possess the equipment, confidence, and time required to navigate the system. That is not security culture. It is a filtering mechanism.

This matters in climate organizing, tenant unions, labor campaigns, migrant solidarity networks, and mutual aid. The people most affected by extraction and austerity often have the least spare capacity for elaborate digital routines. If participation requires a recent smartphone, stable internet access, multiple accounts, and repeated security training, the movement quietly shifts its center of gravity toward the already resourced.

The answer is not to abandon secure communications. It is to distinguish between the security needs of different participants and different stages of participation.

A new volunteer might receive public event information through a simple mailing list or SMS alert. A confirmed volunteer could join a moderated coordination group. A smaller team handling sensitive legal or direct-action information could use Signal with explicit training and tighter membership controls. That layered approach allows the movement to expand without distributing its most sensitive information to everyone who encounters the campaign.

Layering also reduces the damage caused by a single failure. If a public account gets taken down, core coordination can continue. If a volunteer’s phone is lost, the group does not automatically expose its entire strategic archive. If a public mobilization channel attracts harassment, the sensitive team does not have to dissolve its operations.

The goal is not perfect security. Perfect security does not exist under conditions of state surveillance, corporate extraction, and human error. The goal is proportionate security: enough protection for the risk, without imposing such a high cost that ordinary participation becomes impossible.

The safest channel is useless if it turns the movement’s front door into a locked room.

When the internet disappears, app debates become irrelevant

The limits of encrypted messaging become especially clear during shutdowns. A secure application still depends on connectivity unless organizers have built alternative systems in advance.

In Iran, a week-long internet blackout in November 2019 helped drive interest in offline encryption tools such as Nahoft. The tool enabled activists to encode messages into Farsi words or image files without requiring active internet access during the blackout. That kind of adaptation is not a clever app trick. It is a recognition that infrastructure itself can become a weapon.

When governments control connectivity, they control the conditions under which digital security operates. They can throttle networks, block app stores, shut down mobile data, monitor telecommunications providers, or make access too unreliable for ordinary coordination. A movement that plans only for message interception has not planned for communication failure.

Offline tools have their own costs. They require training, compatible practices, and a distribution method that works before the network disappears. They may slow communication and create additional opportunities for mistakes. But that friction reflects a material constraint. No interface redesign can make a disconnected network behave like an open one.

The same principle applies in less dramatic settings. A protest network may face dead phone batteries, crowded cellular networks, confiscated devices, or participants who cannot safely carry a phone. Paper contact trees, physical meeting points, trusted runners, and pre-agreed procedures are not nostalgic substitutes for digital tools. They are redundancy. Movements that depend entirely on one communications layer make themselves fragile.

A practical architecture for grassroots movements

The strongest communications setup usually divides responsibilities instead of searching for a universally secure platform.

A movement can build that structure around several simple decisions:

1. Separate public information from sensitive information.

Publish campaign demands, meeting announcements, and public event details through channels designed for reach. Keep personal data, direct-action planning, and legal exposure inside smaller, controlled groups.

2. Use Signal for the conversations that justify its friction.

Signal is well suited to core teams and known participants who can follow clear security practices. It is not a replacement for public outreach, and it should not become a compulsory doorway for every person interested in the campaign.

3. Treat onboarding as political infrastructure.

New participants need a short explanation of why the group uses particular tools, what information must not be shared, and how to secure their devices. Training should be practical rather than punitive. If people cannot follow the system, the system needs redesign.

4. Reduce the information collected.

Do not build a database of sensitive personal details simply because a form can store them. Keep only what the campaign needs to operate, and establish deletion practices before a crisis forces the question.

5. Plan for account and device loss.

Decide how the group will respond if a phone disappears, an account is compromised, or a platform removes a public page. Recovery procedures should not depend on one person’s memory or one administrator’s access.

6. Maintain a non-digital fallback.

Establish physical meeting points, offline contact methods, and procedures for network outages. These systems are especially important for groups operating under repression or in areas with unreliable connectivity.

7. Review the threat model as conditions change.

A public climate march, a workplace strike, and an action likely to trigger arrests do not carry the same risks. Security should follow the action, the participants, and the power arrayed against them—not the preferences of whichever app happens to be popular.

This architecture demands more organizational discipline than simply telling everyone to download Signal. It also produces a stronger movement. The process forces organizers to decide what they are protecting, from whom, and at what cost.

The political choice is between brittle control and durable participation

Security restrictions can protect a movement from infiltration and surveillance. They can also centralize knowledge, empower administrators, and make participation dependent on technical fluency. That is a political trade-off, not an accidental side effect.

A movement obsessed with control may become operationally tidy and socially irrelevant. A movement obsessed with growth may expose its most vulnerable members to preventable harm. Both failures serve the same broader system: one produces fragmentation, the other produces repression.

The answer lies in distributed capacity. More than one person should know how communications work. More than one channel should carry essential information. More than one generation of participants should understand the rules. Public outreach should remain open enough to grow, while sensitive coordination should remain narrow enough to protect people who face real consequences.

Digital security tools for protesters are instruments, not politics. They can reduce exposure, preserve communication during repression, and give organizers more control over their relationships. They cannot decide which risks deserve protection, which people get access, or whether a campaign connects to the material conditions driving people into the streets.

We should stop asking which app will secure activism. The better question is which communications arrangement lets people participate without making them disposable—and lets a movement grow without turning growth into a surveillance gift.

Encryption belongs inside that arrangement. It cannot substitute for it.

FAQ

Why is using only one encrypted app for all movement activities a bad idea?
It creates friction that discourages new participants and fails to distinguish between public outreach and sensitive coordination, potentially making the movement socially irrelevant.
Does end-to-end encryption prevent authorities from tracking activist relationships?
No, because movements still generate metadata—such as who communicates with whom and when—which can be used to map relationships even if the message content remains unreadable.
What are the most effective ways to improve security beyond just using encrypted apps?
Focus on basic device hygiene, such as using strong PINs, enabling two-factor authentication, updating operating systems, and practicing data minimization by not collecting unnecessary personal information.
How should activist groups handle communication during internet shutdowns?
Groups should establish redundancy by using offline encryption tools, paper contact trees, physical meeting points, and pre-agreed procedures that do not rely on digital connectivity.
Why is it important to separate public information from sensitive planning?
Treating all information as equally sensitive creates needless barriers for new members, while treating everything as harmless creates unnecessary danger for vulnerable participants.